CVE-2021-26857
HIGHCISA KEVRansomware
Microsoft Exchange Server Remote Code Execution Vulnerability
Record summary
CVE-2021-26857 has a selected CVSS score of 7.8 (high); EIP currently links 9 repository PoCs. CISA lists CVE-2021-26857 in KEV and reports its use in known ransomware campaigns.
Description
Microsoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-26412, CVE-2021-26854, CVE-2021-26855, CVE-2021-26858, CVE-2021-27065, CVE-2021-27078.
Description source: GitHub Advisory
Exploitation context
Known exploitation
- CISA KEV
- Listed · Nov 3, 2021 · CISA
- VulnCheck KEV
- Listed · Mar 2, 2021 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
- Ransomware use
- Observed · CISA
Available material
- Repository PoCs
- 9
CISA SSVC decision
ExploitationActive
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 2, 2021 · Source: CVE List
Affected products and versions
Showing 12 of 27| Product | Source | Version range | Status |
|---|---|---|---|
Exchange ServerBrowse Microsoft / Exchange Server | CISA | Version data not supplied | |
Microsoft Exchange Server 2010 Service Pack 3Browse Microsoft / Microsoft Exchange Server 2010 Service Pack 3 | CVE List | 14.0.0.0 to < publication | affected |
Microsoft Exchange Server 2013 Cumulative Update 21Browse Microsoft / Microsoft Exchange Server 2013 Cumulative Update 21 | CVE List | 15.00.0 to < publication | affected |
Microsoft Exchange Server 2013 Cumulative Update 22Browse Microsoft / Microsoft Exchange Server 2013 Cumulative Update 22 | CVE List | 15.00.0 to < publication | affected |
Microsoft Exchange Server 2013 Cumulative Update 23Browse Microsoft / Microsoft Exchange Server 2013 Cumulative Update 23 | CVE List | 15.00.0 to < publication | affected |
Microsoft Exchange Server 2013 Service Pack 1Browse Microsoft / Microsoft Exchange Server 2013 Service Pack 1 | CVE List | 15.00.0 to < publication | affected |
Microsoft Exchange Server 2016 Cumulative Update 10Browse Microsoft / Microsoft Exchange Server 2016 Cumulative Update 10 | CVE List | 15.01.0 to < publication | affected |
Microsoft Exchange Server 2016 Cumulative Update 11Browse Microsoft / Microsoft Exchange Server 2016 Cumulative Update 11 | CVE List | 15.01.0 to < publication | affected |
Microsoft Exchange Server 2016 Cumulative Update 12Browse Microsoft / Microsoft Exchange Server 2016 Cumulative Update 12 | CVE List | 15.01.0 to < publication | affected |
Microsoft Exchange Server 2016 Cumulative Update 13Browse Microsoft / Microsoft Exchange Server 2016 Cumulative Update 13 | CVE List | 15.01.0 to < publication | affected |
Microsoft Exchange Server 2016 Cumulative Update 14Browse Microsoft / Microsoft Exchange Server 2016 Cumulative Update 14 | CVE List | 15.01.0 to < publication | affected |
Microsoft Exchange Server 2016 Cumulative Update 15Browse Microsoft / Microsoft Exchange Server 2016 Cumulative Update 15 | CVE List | 15.01.0 to < publication | affected |
Proofs of concept
9Repository PoCs
GitHubsgnls/exchange-0days-202103Repository PoCby sgnlsStars: 5Not analyzed2 files
GitHubsoteria-security/HAFNIUM-IOCRepository PoCby soteria-securityStars: 22Not analyzed3 files
GitHubcert-lv/exchange_webshell_detectionRepository PoCby cert-lvStars: 99Not analyzed2 files
GitHubYt1g3r/CVE-2021-26855_SSRFRepository PoCby Yt1g3rStars: 4Not analyzed2 files
GitHubDCScoder/Exchange_IOC_HunterRepository PoCby DCScoderStars: 0Not analyzed7 files
GitHubsirpedrotavares/Proxylogon-exploitRepository PoCby sirpedrotavaresStars: 111Not analyzed2 files
GitHubSCS-Labs/HAFNIUM-Microsoft-Exchange-0dayRepository PoCby SCS-LabsStars: 5Not analyzed38 files
GitHubImmersive-Labs-Sec/ProxyLogonRepository PoCby Immersive-Labs-SecStars: 3Not analyzed4 files
GitHubbyinarie/ZirconiumRepository PoCby byinarieStars: 2Not analyzed2 files
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-26857 portal.msrc.microsoft.com
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-26857 cisa.govGovernment resource
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-26857